A Study of Classifying Advanced Persistent Threats With Multi-Layered Deep Learning Approaches
Yen-Hung Frank Hu, Chung-Chu George Hsieh · 2021
Advanced persistent threats have caused serious negative impacts on today’s cyber defense systems because of their stealthy characteristics and sophisticated attacking strategies. Many approaches have been proposed and applied to identify and classify advanced persistent threats. However, there is still a lack of promising solutions for defending against such threats. Research has shown that deep learning can enhance image categorization and classification and provide a potential solution for detecting anomalies. To extend study and investigation of advanced persistent threats, we have proposed multiple-layer deep learning approaches adopting image generation and convolution neural network technology. In this research, more than 3000 portable executable samples belonging to 12 advanced persistent threats were converted into images, then categorized into a training and validation dataset for developing and utilizing the proposed deep learning models. Performance studies and contributions of such models were studied and measured as well.